Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Carp, which interface are sync packets sent over??

    HA/CARP/VIPs
    5
    7
    3.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      RedRocket
      last edited by

      hi guys, most of us have carp setup and the two firewalls syncing over the sync interface. do any of these sync packets pass over the other interfaces, like wan and lan interfaces??

      1 Reply Last reply Reply Quote 0
      • S
        smilodon
        last edited by

        wan - impossible and unreasonable
        lan - can be used
        optX to optX with 1 cable - most secure

        I used the last one.
        But no success with my multiwan setup… total failure.

        1 Reply Last reply Reply Quote 0
        • dotdashD
          dotdash
          last edited by

          The SYNC traffic is only sent over the interface used to sync. There is CARP traffic on the other interfaces.

          1 Reply Last reply Reply Quote 0
          • R
            RedRocket
            last edited by

            would it be possible to setup rules on the WAN interface to block CARP traffic? I dont want the carp traffic escaping my internal network onto the external network??

            Thanks

            1 Reply Last reply Reply Quote 0
            • dotdashD
              dotdash
              last edited by

              CARP, by nature, uses multicast traffic. Any interface on which you have CARP VIPs on will be sending CARP traffic. If you want to limit this for security reasons, your best bet would be to configure your switch to filter the traffic except on the ports where your CARP nodes are.

              1 Reply Last reply Reply Quote 0
              • T
                tehtrk
                last edited by

                @dotdash:

                CARP, by nature, uses multicast traffic. Any interface on which you have CARP VIPs on will be sending CARP traffic. If you want to limit this for security reasons, your best bet would be to configure your switch to filter the traffic except on the ports where your CARP nodes are.

                When adding a new rule to pfsense , I see that you may specify CARP as the protocol. I have experimented with a block rule specifying CARP as the protocol, but it seems to have no effect. I would assume that pf isn't able to block the CARP advertisement packets, but if this is the case, what purpose does that option serve? Does anyone know?

                1 Reply Last reply Reply Quote 0
                • GruensFroeschliG
                  GruensFroeschli
                  last edited by

                  pfSense doesnt filter outbound traffic.
                  CARP traffic leaving pfSense cannot be blocked.
                  And if you have a CARP IP on an interface you wouldnt want to block the CARP traffic, would you?

                  You could use pfSense as a filtering bridge before your network and thus filter CARP-traffic.
                  –> If you have CARP-traffic on your own public subnet you could avoid sending it to the rest of the internet (or at least your ISP).

                  We do what we must, because we can.

                  Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.